Executive brief
A memory corruption vulnerability exists in a Qualcomm component that occurs when processing large input data that exceeds normal allocation limits. An attacker exploiting this issue could cause the component to crash or potentially execute arbitrary code, affecting the availability and security of devices using the vulnerable Qualcomm software.
Technical details
This is a memory corruption vulnerability triggered when copying large input data that exceeds the component's normal memory allocation limits. The vulnerable component fails to properly validate or handle oversized input, leading to out-of-bounds memory access. The attack requires network access to send the large input data to the affected component. A successful exploit can result in denial of service through a crash or, under certain conditions, arbitrary code execution, depending on the memory layout and exploitation technique employed.
Affected products
- Qualcomm <UNKNOWN>
Timeline
- 2026-09-17: disclosed